Senior Administrator, Systems Management
Our team members are at the heart of everything we do. At Cencora, we are united in our responsibility to create healthier futures, and every person here is essential to us being able to deliver on that purpose. If you want to make a difference at the center of health, come join our innovative company and help us improve the lives of people and animals everywhere. Apply today!
Job Details
Senior Administrator (Level 3) responsible for the design, deployment, and advanced support of endpoint management solutions across a large, distributed physical and virtual device estate using Microsoft Endpoint Configuration Manager (MECM) and Microsoft Intune in a co-managed environment. Owns application packaging, third-party patch management, security vulnerability remediation, advanced PowerShell automation, and at-scale incident troubleshooting, partnering closely with Information Security, Networking, and Support teams to keep the endpoint fleet secure, compliant, and reliable.
Key Responsibilities
- Package, test, and deploy Windows and third-party applications through MECM and Intune (Win32 apps), using PSADT and other silent-install packages with reliable detection logic and dependency handling.
- MECM/Intune co-management experience: client settings, boundaries and boundary groups, deployment collections, Autopilot profiles, compliance policies, and configuration baselines across the enterprise endpoint estate.
- Design, write, and maintain advanced PowerShell scripts for automation, remediation, and reporting, including Intune and MECM.
- Identify, prioritize, and remediate security vulnerabilities across the endpoint fleet in partnership with Information Security – driving CVE/patch-compliance reporting and mitigation timelines for OS and third-party applications.
- Third-party application patching lifecycle – identifying, packaging, testing, and deploying updates (e.g., via Patch My PC, MECM, application/patch deployment) to minimize vulnerability exposure windows.
- Networking knowledge (DNS, DHCP, IP addressing/subnetting, VLANs, boundary/content distribution) to resolve connectivity issues affecting client communication, application delivery, and patch distribution.
- Leverage AI-assisted tools (Claude, Copilot and other scripting assistants) and automation/orchestration to streamline packaging, remediation, and reporting – tracking work in JIRA and version-controlling scripts/configs in GitHub.
- Partner and collaborate with multiple technical teams (Architecture, Networking, Information Security, Support, etc.) to develop and support endpoint solutions.
- Triage and resolve escalations from Endpoint Support and Security, acting as a technical escalation point for Level 1/2 teams.
This job profile description is a standardized, non-contractual reference description and global reference tool provided for organizational consistency and talent architecture purposes across Cencora. It does not alter actual job duties, responsibilities, reporting lines, working conditions, grading, compensation, or other essential terms and conditions of employment.
Actual duties and responsibilities may vary based on business needs, local requirements, and operational practices. Where a team member's role is governed by an employment agreement, local terms and conditions, prior job description or collective bargaining agreement, those documents shall prevail in case of any inconsistency. Mandatory local laws shall also prevail.
Experience and Educational Requirements
- Bachelor's degree, preferably in Computer Science, Management Information Systems, or a related technology field (equivalent experience considered).
- At least 8 years of IT experience, including 5+ years in infrastructure/endpoint engineering.
- Advanced, hands-on expertise with Microsoft Endpoint Configuration Manager (MECM/SCCM) and Microsoft Intune, including co-management, Autopilot, compliance policies, and Win32 application deployment.
- Demonstrated experience remediating security vulnerabilities – identifying, prioritizing, and patching OS and third-party application vulnerabilities, including CVE triage and patch-compliance reporting (Microsoft Defender/vulnerability management tooling).
- Advanced PowerShell scripting ability (functions, modules, error handling, remoting, Graph API/Intune scripting), plus familiarity with VBScript for legacy support.
- Proven ability to troubleshoot complex incidents at scale across large, distributed endpoint environments, with strong root-cause analysis skills.
- Strong application packaging experience (.MSI/.MST, Win32; App-V/MSIX familiarity a plus) using, PSAppDeployToolkit, Advanced Installer, and Orca.
- Experience managing third-party application patching programs (e.g., Patch My PC, Ivanti, or similar).
- Solid understanding of Active Directory and Group Policy for managing user/computer objects, including GPO troubleshooting (gpresult, RSoP).
- Working knowledge of wired/wireless networking fundamentals: DHCP, DNS, IP addressing, subnetting, and VLANs, and how they affect client-server communication and content distribution.
- Familiarity with Windows 11 Enterprise features, settings, and deployment; BIOS/UEFI configuration; Bitlocker and Microsoft Defender.
- Experience with virtualization technologies (Citrix, VMware) and thin/zero-client delivery is a plus.
- Solid track record of delivering thoughtful, effective, and timely solutions to complex business problems that enhance the end-user experience.
Additional / Preferred Skills
- AI-assisted automation and Copilot-style tools (Microsoft Copilot, GitHub Copilot, Claude) to speed up scripting, triage, and remediation.
- Service-Now for Incident, request logging.
- GitHub (or Azure DevOps) for version-controlled scripts and Intune/MECM configuration-as-code, including basic CI/CD pipelines.
- JIRA (or similar) for ticketing, sprint/backlog tracking, and change management.
- Working familiarity with Azure AD/Microsoft Entra ID, conditional access, and Windows Autopatch.
- Experience mentoring Level 1/2 engineers and producing clear runbooks/knowledge-base documentation.
- ITIL foundations or equivalent incident/problem/change management experience.
What Cencora offers
We provide compensation, benefits, and resources that enable a highly inclusive culture and support our team members’ ability to live with purpose every day. In addition to traditional offerings like medical, dental, and vision care, we also provide a comprehensive suite of benefits that focus on the physical, emotional, financial, and social aspects of wellness. This encompasses support for working families, which may include backup dependent care, adoption assistance, infertility coverage, family building support, behavioral health solutions, paid parental leave, and paid caregiver leave. To encourage your personal growth, we also offer a variety of training programs, professional development resources, and opportunities to participate in mentorship programs, employee resource groups, volunteer activities, and much more. For details, visit
Full timeEqual Employment Opportunity
Cencora is committed to providing equal employment opportunity without regard to race, color, religion, sex, sexual orientation, gender identity, genetic information, national origin, age, disability, veteran status or membership in any other class protected by federal, state or local law.
The company’s continued success depends on the full and effective utilization of qualified individuals. Therefore, harassment is prohibited and all matters related to recruiting, training, compensation, benefits, promotions and transfers comply with equal opportunity principles and are non-discriminatory.
Affiliated Companies
Affiliated Companies: AmerisourceBergen Services CorporationRequired Skills
Required Languages
🇬🇧 English